{"id":"CVE-2026-70622","title":"tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…","summary":"tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-59","CWE-22"],"published":"2026-08-10","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:43:32.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-70622","references":[{"url":"https://gist.github.com/thesmartshadow/e7dac0bb690ee17b9cc142154cb11726","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tar-rs-symlink-escape-via-append-dir-all","label":"disclosure@vulncheck.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-70622.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-70622"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2513575"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-70622"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70622"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.0046,"epssPercentile":0.37132,"ingestedAt":"2026-09-24T20:51:40.188Z","vendor":"Red Hat","product":"Red Hat OpenShift Update Service","affected":["openshift_update_service"],"slug":"CVE-2026-70622","body":"## Overview\n\ntar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-controlled directory. When a privileged process archives an untrusted directory, the function follows symlinks without verifying that resolved targets remain within the source root, causing out-of-bounds files to be included in the archive as regular files and disclosed to the attacker.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift Update Service · no fix planned: Red Hat OpenShift Update Service · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-70622.json)","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}